cve/2024/CVE-2024-9981.md
2025-09-29 21:09:30 +02:00

883 B

CVE-2024-9981

Description

The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to upload a malicious PHP file first and then exploit this vulnerability to include the file, resulting in arbitrary code execution on the server.

POC

Reference

No PoCs from references.

Github